2014年4月2日水曜日

2日 水曜日、大安

+ RHSA-2014:0348 Important: xalan-j2 security update
http://rhn.redhat.com/errata/RHSA-2014-0348.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0107

+ About the security content of Safari 6.1.3 and Safari 7.0.3
http://support.apple.com/kb/HT6181
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2871
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2926
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2928
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1289
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1290
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1291
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1292
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1293
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1294
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1298
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1299
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1300
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1301
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1302
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1303
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1304
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1305
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1307
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1308
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1309
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1310
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1311
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1312
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1313
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1713
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1297

+ CESA-2014:0342 Moderate CentOS 6 wireshark Update
http://lwn.net/Alerts/592658/

+ CESA-2014:0341 Moderate CentOS 5 wireshark Update
http://lwn.net/Alerts/592657/

+ HPSBHF02981 - rev.1 - HP Integrated Lights-Out 2, 3 and 4 (iLO2, iLO3, iLO4), IPMI 2.0 RCMP+ Authentication Remote Password Hash Vulnerability (RAKP)
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04197764-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4786

+ Multiple vulnerabilities in PHP
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_php2
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1635
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1643

+ CVE-2013-4113 Buffer Errors vulnerability in PHP
https://blogs.oracle.com/sunsecurity/entry/cve_2013_4113_buffer_errors
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4113

+ Multiple vulnerabilities in PHP
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_php1
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4718
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2110
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4113
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4248
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4635
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4636

+ Multiple vulnerabilities in PHP
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_php
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2688
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3365

+ Multiple vulnerabilities in Memcached
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_memcached
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0179
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7239
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7290
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7291

+ CVE-2014-2469 Denial of Service(DoS) vulnerability in Lighthttpd
https://blogs.oracle.com/sunsecurity/entry/cve_2014_2469_denial_of
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2469

+ Multiple vulnerabilities in Lighthttpd
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_lighthttpd
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0295
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1427

+ CVE-2013-1849 Denial of Service(DoS) vulnerability in Apache Subversion
https://blogs.oracle.com/sunsecurity/entry/cve_2009_0179_denial_of1
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1849

+ CVE-2013-4505 Permissions, Privileges and Access Control vulnerability in Apache Subversion
https://blogs.oracle.com/sunsecurity/entry/cve_2013_4505_permissions_privileges
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4505

+ CVE-2013-4365 Buffer Errors vulnerability in Apache
https://blogs.oracle.com/sunsecurity/entry/cve_2013_4365_buffer_errors
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4365

+ CVE-2013-2236 Buffer Errors vulnerability in Quagga
https://blogs.oracle.com/sunsecurity/entry/cve_2013_2236_buffer_errors
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2236

+ CVE-2013-4396 Use-after-free vulnerability in X.Org
https://blogs.oracle.com/sunsecurity/entry/cve_2013_4396_use_after
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4396

+ CVE-2014-1912 Buffer Errors vulnerability in Python
https://blogs.oracle.com/sunsecurity/entry/cve_2014_1912_buffer_errors
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1912

+ CVE-2007-6750 Resource Management Errors vulnerability in Apache
https://blogs.oracle.com/sunsecurity/entry/cve_2007_6750_resource_management1
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750

+ Multiple vulnerabilities in Tomcat
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_tomcat
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3544
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2067

+ Multiple vulnerabilities in Apache Tomcat
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_apache_tomcat3
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2733
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3546
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4431
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4534
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5885
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5886
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5887

+ Tomcat 7.0.53 Released
http://tomcat.apache.org/tomcat-7.0-doc/changelog.html

+ Linux Kernel 3.14 RDS NULL pointer dereference and system crash
http://cxsecurity.com/issue/WLB-2014040007
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2678

+ Linux Kernel 3.12.3 ioctx_alloc local system crash
http://cxsecurity.com/issue/WLB-2014040006
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7348

ゆうちょ銀行をかたるフィッシングが再び出現
http://itpro.nikkeibp.co.jp/article/NEWS/20140401/547702/?ST=security

60台のHDD/SSDを一斉に上書き消去する専用装置
http://itpro.nikkeibp.co.jp/article/NEWS/20140401/547689/?ST=security

企業の情報セキュリティ関連投資は増加傾向――IDC Japan調査
http://itpro.nikkeibp.co.jp/article/NEWS/20140401/547425/?ST=security

VU#893726 Zyxel P660 series modem/router denial of service vulnerability
http://www.kb.cert.org/vuls/id/893726

VU#163188 Pearson eSIS Enterprise Student Information System XSS vulnerability
http://www.kb.cert.org/vuls/id/163188

REMOTE: PhonerLite 2.14 SIP Soft Phone - SIP Digest Disclosure
http://www.exploit-db.com/exploits/32643

REMOTE: SePortal SQLi - Remote Code Execution
http://www.exploit-db.com/exploits/32621

REMOTE: plexusCMS 0.5 - XSS Remote Shell Exploit & Credentials Leak
http://www.exploit-db.com/exploits/32618

0 件のコメント:

コメントを投稿